Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\SRDSLFT] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\SRDSLFT] 'ImagePath' = '%WINDIR%\cresa.exe'
- 'SRDSLFT' %WINDIR%\cresa.exe
- %ALLUSERSPROFILE%\arphacrashreport.exe
- %ALLUSERSPROFILE%\arphadump.dll
- %WINDIR%\arphadump.dll
- %WINDIR%\cresa.exe
- %ALLUSERSPROFILE%\arphacrashreport.exe в %WINDIR%\syswow64\859893.bak
- DNS ASK 8.###205.com
- DNS ASK vi###000a.com
- '%ALLUSERSPROFILE%\arphacrashreport.exe'
- '%WINDIR%\cresa.exe'
- '%WINDIR%\cresa.exe' Win7